CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Infected Notepad files

 
Post new topic   Reply to topic       All -> FavForums -> Unknown Files [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
John B.

1st Responder


Joined: Dec 03, 2006
Posts: 843
Location: Netherlands
1st Responders

PostPosted: Sun Feb 17, 2008 12:31 pm    Post subject: Infected Notepad files
Reply with quote

Hi,

All my speeches to OPs, and the notes I make, I save in Notepad files. Like one month ago I did a Kaspersky scan on my desktop and it showed two infected Notepad files. I removed them. Last week I did a scan on this laptop where I regularly copy the documents of my desktop to, and it showed those infected Notepad files.

I am interested what could be infected in a Notepad file with plain text. It may also be good to send samples to AV companies so I thought it'd be good to send you the files.

Virustotal results (one of the two files, but they have the same infection):
AhnLab-V3 - - -
AntiVir - - HTML/Exploit.Mhtml
Authentium - - -
Avast - - -
AVG - - -
BitDefender - - -
CAT-QuickHeal - - -
ClamAV - - -
DrWeb - - -
eSafe - - -
eTrust-Vet - - -
Ewido - - -
FileAdvisor - - -
Fortinet - - -
F-Prot - - -
F-Secure - - HTML/Exploit!Mht.A
Ikarus - - -
Kaspersky - - Exploit.HTML.Mht
McAfee - - Exploit-MhtRedir.gen
Microsoft - - -
NOD32v2 - - -
Norman - - HTML/Exploit!Mht.A
Panda - - -
Prevx1 - - -
Rising - - -
Sophos - - -
Sunbelt - - -
Symantec - - Bloodhound.Exploit.6
TheHacker - - -
VBA32 - - -
VirusBuster - - VBS.Casino.A
Webwasher-Gateway - - Script.Exploit.Mhtml
Additional information
MD5: 02275b42876da49b85c61f3b6fdc6ecc
SHA1: 79fa7cdc5c2b0f2bb1f27afaab9f591f009e93c6
SHA256: 8ed18e062e95261cff32f9193de19b8401fd4c2bd57195f1896dafbded3ae7fc
SHA512: 90085e4f07dc6896f60cb63e7aa27615bd430e9f6ce67249679bc49a1a08ed0b bb5ced64ef151ba15d7c30ae1fa5ac927bc0b9137f29a042c4eb578af74bd9c0

Files are attached in archive with password.

Greets, John.


_________________
Trained by MalWare Removal

Proud member of ASAP - Alliance of Security Analysis Professionals

Proud member of UNITE - Unified Network of Instructors and Trusted Eliminators
Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5879

MIRT Premium

PostPosted: Sun Feb 17, 2008 3:12 pm    Post subject:
Reply with quote

In both files it's line O16 which is causing the problem. If you copy just that line into a .txt file and scan it you'll probably get the same results.

Years ago I remember a bad exploit that starts off looking similar to that line.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
John B.

1st Responder


Joined: Dec 03, 2006
Posts: 843
Location: Netherlands
1st Responders

PostPosted: Sun Feb 17, 2008 3:29 pm    Post subject:
Reply with quote

But opening the Notepad file will not 'run' the malware? How can it be that only this line is recognized and the hundreds of other lines in other Notepad files not?


_________________
Trained by MalWare Removal

Proud member of ASAP - Alliance of Security Analysis Professionals

Proud member of UNITE - Unified Network of Instructors and Trusted Eliminators
Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5879

MIRT Premium

PostPosted: Sun Feb 17, 2008 9:57 pm    Post subject:
Reply with quote

No it won't run it. That line is recognised because I think it can be put into web pages to run the exploit.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
John B.

1st Responder


Joined: Dec 03, 2006
Posts: 843
Location: Netherlands
1st Responders

PostPosted: Mon Feb 18, 2008 6:57 am    Post subject:
Reply with quote

Thanks tetak Smile


_________________
Trained by MalWare Removal

Proud member of ASAP - Alliance of Security Analysis Professionals

Proud member of UNITE - Unified Network of Instructors and Trusted Eliminators
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Unknown Files All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer